Skip to main content

Configuring Multiple LDAP Servers

  • July 10, 2017
  • 4 replies
  • 20 views

Jim_Knicely
Forum|alt.badge.img+2

Hi,

I'm trying to test the ability to "Configuring Multiple LDAP Servers". Actually, I want to connect to the same LDAP server but with a different base_dn and priority for each authentication entry. (I have a client that has user in different OUs in the same tree,)

I created two LDAP authentication methods like this:

DROP AUTHENTICATION vldap1 CASCADE;
CREATE AUTHENTICATION vldap1 METHOD 'ldap' LOCAL;
GRANT AUTHENTICATION vldap1 TO public;
ALTER AUTHENTICATION vldap1 SET 
host='ldap://xx.xx.xx.xx/',
basedn='ou=verticausers,dc=mydomain,dc=com',
binddn='cn=root,dc=mydomain,dc=com',
bind_password='xxxx';
ALTER AUTHENTICATION vldap1 PRIORITY 1;

DROP AUTHENTICATION vldap2 CASCADE;
CREATE AUTHENTICATION vldap2 METHOD 'ldap' LOCAL;
GRANT AUTHENTICATION vldap2 TO public;
ALTER AUTHENTICATION vldap2 SET 
host='ldap://xx.xx.xx.xx/',
basedn='cn=admin,ou=organizationalUnit,dc=mydomain,dc=com', 
binddn='cn=root,dc=mydommain,dc=com',
bind_password='1234';
ALTER AUTHENTICATION vldap2 PRIORITY 0;

I have 2 users defined in LDAP:

Distinguished Name: cn= blank_admin,cn=admin,ou=organizationalUnit,dc=mydomain,dc=com
Distinguished Name: cn= blank,cn=generic,ou=verticausers,dc=mydomain,dc=com

Here they are in Vertica:

dbadmin=> select * from user_client_auth where user_name in ('blank', 'blank_admin');
     user_oid      |  user_name  |     auth_oid      | auth_name | granted_to
-------------------+-------------+-------------------+-----------+------------
 45035996274640894 | blank       | 45035996274647600 | vldap1    | public
 45035996274640894 | blank       | 45035996274647604 | vldap2    | public
 45035996274641936 | blank_admin | 45035996274647600 | vldap1    | public
 45035996274641936 | blank_admin | 45035996274647604 | vldap2    | public
(4 rows)

When I try to log in as the user blank, it works fine:

[dbadmin@localhost ~]$ vsql -U blank -w test123 -c "select client_authentication_name from sessions;"
 client_authentication_name
----------------------------
 vldap1
(1 row)

But logging in as blank_admin fails:

[dbadmin@localhost ~]$ vsql -U blank_admin -w test123 -c "select client_authentication_name from sessions;"
vsql: FATAL 3846:  LDAP authentication failed for user "blank_admin"

I was hoping that it would use the vldap2 authentication method...

So, when I drop the vldap1 authentication method, I can then log in as the blank_admin user:

[dbadmin@localhost ~]$ vsql -c "drop authentication vldap1 cascade;"
DROP AUTHENTICATION

[dbadmin@localhost ~]$ vsql -U blank_admin -w test123 -c "select client_authentication_name from sessions;"
 client_authentication_name
----------------------------
 vldap2
(1 row)

So, the question is, why does this not work when vldap1 exists? Why does Vertica not continue on to vldap2 when it fails on vldap1?

Thanks!

4 replies

Car1os
Forum|alt.badge.img
  • Participating Frequently
  • July 10, 2017

I think this can be fixed using ldap_continue parameter. From our docs:

If the highest priority method is LDAP and authentication fails, Vertica searches for the next highest priority LDAP method. Authentication attempts continue until the authentication is successful, or there are no additional LDAP authentication methods that satisfy the connection criteria.
Note that if a user not found error occurs during LDAP authentication, the retry connection attempt initiates only if you set the ldap_continue parameter to yes.

https://my.vertica.com/docs/8.1.x/HTML/index.htm#Authoring/Security/ClientAuth/PrioritiesForClientAuthenticationMethods.htm


Jim_Knicely
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • July 10, 2017

That was it! Thanks, Car1os !!! Note that I only had to add ldap_continue='yes' to vldap1. Awesome :smiley:


Jim_Knicely
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • July 10, 2017

Along the same line, is it possible to have LDAP link sync users from the same LDAP server where users are in different search bases? Following the examples above, I tried to create a link using LDAPLinkSearchBase = 'ou=verticausers,dc=mydomain,dc=com' and Vertica did sync the "blank" user, but it deleted the "blank_admin" user. Then I altered the LDAPLinkSearchBase to 'cn=admin,ou=organizationalUnit,dc=thegeekstuff,dc=com' and then Vertica deleted the "blank" user and synced the "blank_admin" user...

Is it possible to sync to 2 different search bases on the same server?


Car1os
Forum|alt.badge.img
  • Participating Frequently
  • July 10, 2017

I think you can only sync with one LDAP, the settings for it are at the database level, so any changes will overwrite the previous settings.